7.2
CVE-2026-7534
- EPSS 0.19%
- Veröffentlicht 23.07.2026 05:35:53
- Zuletzt bearbeitet 23.07.2026 15:14:51
- CVE-Watchlists
- Unerledigt
SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter
SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the custom `rs_earning_read` capability to all users — including unauthenticated visitors — combined with missing sanitization of the `reason` parameter in the `create_items()` function and missing output escaping in the `column_default()` method of `SRP_Master_Log`. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the reward points log that will execute whenever an administrator accesses the Master Log or User Reward Points admin pages.
Mögliche Gegenmaßnahme
SUMO Reward Points for WooCommerce: Update to version 32.8.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFantasticPlugins
≫
Produkt
SUMO Reward Points for WooCommerce
Default Statusunaffected
Version <=
32.7.0
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
SUMO Reward Points for WooCommerce
Version
*-32.7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.089 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 7.2 | 3.9 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://www.wordfence.com/threat-intel/vulnerabilities/id/366b5051-d042-4425-9aad-b77d93bcd485?source=cve
https://codecanyon.net/item/sumo-reward-points-woocommerce-reward-system/7791451
https://www.wordfence.com/threat-intel/vulnerabilities/id/366b5051-d042-4425-9aad-b77d93bcd485